The stupid question is the question not asked | |
PerlMonks |
Re^2: XSS Protection in cgi applicationby Fletch (Bishop) |
on Nov 03, 2021 at 15:18 UTC ( [id://11138385]=note: print w/replies, xml ) | Need Help?? |
I started to comment along similar lines. He's expecting you to make his Model T able to fuel up at a Tesla supercharging station and (of course) needs it by last week . . . You should point out to your boss that in order to give an ancient CGI script the protections of a decade-or-so worth of development of security improvements that have gone into more modern frameworks he should expect to need a decade-or-so of work backporting them. There'll probably be some low hanging fruit you can integrate as was mentioned upthread but you'll have to do the work to wire it in yourself (which also means you get fewer eyeballs on it; possibly enough to placate the scanning ones, at least, maybe). Of course even if you rewrite using something modern those improvements are just a more solid foundation upon which you can build and you still need to pay attention to best practices while you rebuild. They just make it harder, not impossible, to get your foot under the barrel. Edit: The reply below will probably get reaped shortly but you can simulate the experince quite easily.
The cake is a lie.
In Section
Seekers of Perl Wisdom
|
|